🪟 Windows ServerMicrosoft bestätigt Copy & Paste-Problem in Excel - BornCity(16.09.2026 um 20:56 Uhr)
🪟 Windows ServerMicrosoft bestätigt Copy & Paste-Problem in Excel - BornCity(16.09.2026 um 20:56 Uhr)
🔧 Programmierung 🕛 vor 2 Monaten 2 Min Lesezeit
0

The Microsoft UEFI CA from 2011 expired last week. Here's what to check.

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

The Microsoft UEFI CA 2011 quietly expired on June 27, 2026. If you're running anything with Secure Boot enabled, this is worth five minutes of your time.






What actually breaks



Third-party binaries that were signed only by that CA — things like option ROMs, older third-party bootloaders, or hardware firmware blobs — can fail Secure Boot validation. The machine may refuse to boot, or just silently skip what it can't verify.



The good news: most major Linux distros pushed dual-signed shim binaries in time. Debian, Ubuntu, Fedora — they're all covered. If you've been keeping up with updates, you're probably fine.






Who probably needs to act





  • Self-hosted bare metal with custom partitions or hardware RAID controllers that carry their own Option ROMs


  • Edge devices that haven't been touched in a while — routers, appliances, IoT gateways running older firmware


  • VMs on older hypervisors where the firmware blob hasn't been updated

  • Anything running Secure Boot on hardware that predates 2022






How to check



On a Linux system with Secure Boot enabled:



\`bash






Check what UEFI vars are loaded



cat /sys/firmware/efi/efivars/SecureBoot*






See what keys are enrolled



ls /sys/firmware/efi/efivars/ | grep -i db

`\



If you're seeing boot failures that coincide with June 27 or later, that's your culprit.






What to do





  1. Update firmware on affected hardware — most vendors have pushed updated Option ROMs


  2. Update your bootloader shim if you're on an older distro that missed the window — grab a recent signed shim from your distro's repos


  3. Check the shim-review repo if you're a hardware vendor or maintain a custom bootloader: the new dual-signed shims are all documented there



The shim-review team processed 21 reviews in a few weeks to handle this. Most distros got it done. The outliers are the devices nobody has touched in three years.



Worth a quick audit if you manage anything outside the normal update cycle.

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft explained why Windows 11 dropped these Windows 10 features
1 Quelle
Windows 11: Microsoft zwingt Cloud-Migration statt lokaler PC-Übertrag - BornCity
1 Quelle
Microsoft bestätigt Copy & Paste-Problem in Excel - BornCity
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The Microsoft UEFI CA from 2011 expired last week. Here's what to check.

Thematisch verwandte Begriffe: Microsoft, UEFI, from, 2011 · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...